Live data from Hacker News

Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

ciphercue.com

11–20 of 101 posts

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#11

Earlier quoted context omitted.

It’s not a popularly held mindset, either within the security industry or outside of it. This piece seems to be pitched at salespeople whose only job is to extract money from other companies. Basic hygiene security hygiene pretty much removes ransomware as a threat.

> Basic hygiene security hygiene pretty much removes ransomware as a threat. It does not. The problem is, as long as there are people employed in a company, there will be people being too trustful and executing malware, not to mention AI agents. And even if you'd assume people and AI agents were perfect, there's all the auto updaters these days that regularly get compromised because they are such juicy targets. And n…

AFAIK the idea is to have backups so good, that restoring them is just a minor inconvenience. Then you can just discard encrypted/infected data and move on with your business. Of course that's harder to achieve in practice.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#12

Earlier quoted context omitted.

> Basic hygiene security hygiene pretty much removes ransomware as a threat. It does not. The problem is, as long as there are people employed in a company, there will be people being too trustful and executing malware, not to mention AI agents. And even if you'd assume people and AI agents were perfect, there's all the auto updaters these days that regularly get compromised because they are such juicy targets. And n…

AFAIK the idea is to have backups so good, that restoring them is just a minor inconvenience. Then you can just discard encrypted/infected data and move on with your business. Of course that's harder to achieve in practice.

In the end the limiting factor will be the bandwidth of your disk arrays... enough compromised machines and they will get overwhelmed.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#13

It seems obvious to me that the only real solution is to penalize the payment of ransoms. For the same reasons one doesn't negotiate with terrorists. Is there some reason to believe that this isn't the best approach? And if not, then any theories as to why it hasn't been enacted?

All that does is make the problem more expensive by whatever cut the middle men who will pop up take and however much the overhead of the obfuscation is. It might reduce payments at the margin, but probably not enough to be worth the cost.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#16

I don't think there is a reasonable correlation, since stopping ransomware doesn't require that much of an increase in spending; it's a culture thing more than a money thing.

Moving security tickets to the top of the stack is absolutely a money thing. Training is a money thing. Exchanging velocity for security is a money thing. Changing culture takes money.

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#17

It seems obvious to me that the only real solution is to penalize the payment of ransoms. For the same reasons one doesn't negotiate with terrorists. Is there some reason to believe that this isn't the best approach? And if not, then any theories as to why it hasn't been enacted?

It's one of those ideas that sounds nice in theory, but doesn't survive contact with the real world. In the same way that many people would say that you shouldn't negotiate with terrorists or kidnappers; but if it's their loved one who's being held and tortured they'll very quickly change their mind.

Getting to a world where no one pays ransoms and the ransomware groups give up and go away would be the ideal, and we'd all love to get there. But outlawing paying ransoms basically sacrificing everyone who gets ransomwared in the meantime until we get to that state for the greater good.

And where companies get hit, they'll try hard to find ways around that, because the alternative may well be shutting down the business. But if something like a hospital gets hit, are governments really going to be able to stand behind the "you can't pay a ransom" policy when that could directly lead to deaths?

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#18

Earlier quoted context omitted.

> Basic hygiene security hygiene pretty much removes ransomware as a threat. It does not. The problem is, as long as there are people employed in a company, there will be people being too trustful and executing malware, not to mention AI agents. And even if you'd assume people and AI agents were perfect, there's all the auto updaters these days that regularly get compromised because they are such juicy targets. And n…

AFAIK the idea is to have backups so good, that restoring them is just a minor inconvenience. Then you can just discard encrypted/infected data and move on with your business. Of course that's harder to achieve in practice.

Sleeper agent malware is a thing especially in high risk situations. If somebody has a dormant RAT installed since year X-1 it’s going to be impossible to solve that in year X by using backups

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#19

It seems obvious to me that the only real solution is to penalize the payment of ransoms. For the same reasons one doesn't negotiate with terrorists. Is there some reason to believe that this isn't the best approach? And if not, then any theories as to why it hasn't been enacted?

I don't think you can enforce such a rule. I think it's a good approach too. Another issue is that not paying up and risking restore from underfunded ops dept. might be more expensive than paying up AND making a selected executive look bad. And we can't have that, can we.

Agreed - it’s not that it’s a bad point but it would be an ineffective rule which is usually an excuse to forgo other more effective (usually more expensive) options

Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It

#20

It seems obvious to me that the only real solution is to penalize the payment of ransoms. For the same reasons one doesn't negotiate with terrorists. Is there some reason to believe that this isn't the best approach? And if not, then any theories as to why it hasn't been enacted?

I don't think you can enforce such a rule. I think it's a good approach too. Another issue is that not paying up and risking restore from underfunded ops dept. might be more expensive than paying up AND making a selected executive look bad. And we can't have that, can we.

It would make the ransomware statistic go down without actually stopping crime. Any company that considers paying the ransom would have a strong incentive to never report the security incident to avoid being punished for ransom payments
Post reply on HN